We’re Hiring: Security Operations Engineer
Looking for a role that fosters collaboration, creativity and career growth in a vibrant office environment? We got you covered!
Join our team at Cloudstaff, the #1 workplace everywhere! Think you qualify for the role?
Role: Security Operations Engineer
Work Arrangement: Hybrid
Location: Philippines - Makati/Ortigas/Pampanga (Angeles)
Schedule: Morning Shift
Job Description:
The Security Operations Engineer runs the business-as-usual security services stack deployed, working with Microsoft 365 E3 and Microsoft Intune, Rapid7 and the Netskope suite to protect the environment spanning Microsoft 365, Microsoft Azure and Amazon Web Services (AWS). The role works closely with the SOC Analyst to tune metrics and feeds into the Security Information and Event Management (SIEM) platform, and leads vulnerability and patch management.
Key Responsibilities:
- Operate the Nexgen Rapid7 Security Information and Event Management (SIEM) platform, ingesting logs from Microsoft Entra ID, Microsoft 365, AWS CloudTrail and AWS GuardDuty.
- Tune SIEM alerts, severity classification and incident workflow with the SOC Analyst, feeding refined metrics into the platform.
- Lead vulnerability management using Rapid7 and Microsoft Defender for Cloud scanning across Azure and AWS.
- Run patch management through Microsoft Intune for workstations and AWS Systems Manager for the SOHO and Digital applications.
- Operate CrowdStrike Endpoint Detection and Response or Microsoft Defender (EDR) and application whitelisting, driving full endpoint coverage.
- Deploy and validate immutable backups with Veeam and AWS Backup covering Microsoft 365 and AWS workloads.
Parallel and Cross-Functional Responsibilities
- Help cover Security Operations Centre (SOC) triage overflow and alert tuning alongside the SOC Analyst.
- Provide cloud security posture support to the DevSecOps Engineer across AWS and Azure, including Security Hub and Defender for Cloud.
- Provide endpoint hardening support to the M365 Engineer, applying Essential Eight aligned Intune baselines, and support Data Loss Prevention (DLP) operations across Microsoft Purview and Netskope.
Technical Environment
- Rapid7 as the Security Information and Event Management (SIEM), vulnerability scanning and tracking platform
- Microsoft 365 E3 with Microsoft Intune, Microsoft Defender, Microsoft Purview and Microsoft Entra ID, providing native telemetry into the SIEM.
- The Netskope suite for secure web gateway, Data Loss Prevention (DLP), always-on Virtual Private Network (VPN) and Cloud Access Security Broker (CASB).
- CrowdStrike or Microsoft Defender for Endpoint Detection and Response (EDR), Cloudflare for Web Application Firewall (WAF) and Distributed Denial of Service (DDoS) protection, LastPass for password management, and Veeam and AWS Backup for backup independence.
Qualifications and requirements:
Required Skills and Experience
- Demonstrated experience operating a Security Information and Event Management (SIEM) platform such as Rapid7 or Microsoft Sentinel.
- Hands‑on vulnerability and patch management experience across cloud and endpoint estates.
- Working knowledge of Endpoint Detection and Response (EDR) and application whitelisting operations.
- Practical security experience across Amazon Web Services (AWS) and Microsoft Azure, with confidence in Microsoft 365 E3, Microsoft Intune and Microsoft Entra ID administration.
Highly Desirable
- Experience with Rapid7 for vulnerability scanning and the Netskope suite for secure web gateway and Cloud Access Security Broker (CASB).
- Familiarity with Microsoft Defender or CrowdStrike Endpoint Detection and Response (EDR) and Cloudflare protection services.
- Exposure to backup and disaster recovery tooling such as Veeam and AWS Backup, and to the Essential Eight and Centre for Internet Security (CIS) benchmarks.
- A security certification such as Microsoft Certified: Security Operations Analyst Associate or AWS Certified Security.
Non‑negotiable skills and requirements:
- A relevant tertiary qualification in information technology, cyber security or a related field, or equivalent experience.
Perks & Benefits (Work From Office/Hybrid):
- Comprehensive health and life insurance on your 16th day of employment, covering 1 free dependent on the 16th day of employment
- Up to 24 leave credits per year
- Flexible leave credits which may be used for vacation, emergency and sick leaves
- Endless opportunities for career advancement
- Exclusive ATM inside the office for employee's convenience
- Annual Performance Review with Salary Increase
- We set you up for success with a company-provided PC/Laptop and fiber internet connection
- Look forward to weekly office perks for work from office staff – Free Coffee, Meals and Beer Fridays!
- Top notch workplace with first class VIP lounge and game rooms
- Child friendly spaces to cater to the needs of employees with children, enhancing work‑life balance
- Participate and join our CS Social Clubs and Special Interest Groups to connect with colleagues
- Mental Wellness Employee Assistance program through Lifeworks
- In‑house psychiatrist available to support employees' well‑being
- Become part of the Employee Share Units program
- Cloudstaff Dream Points - To be used for bidding useful items like appliances, kitchenettes etc.
Cloudstaff : Build Your Career, Anywhere
Established in 2005, Cloudstaff is a leading outsourcing company that empowers businesses to thrive through smarter talent solutions. We’re passionate about creating a work environment that fosters your professional growth and overall well‑being.
Why Cloudstaff is the #1 Workplace?
- Award‑winning Culture: We’re committed to building the #1 Workplace Everywhere, with a proven track record of staff engagement initiatives and industry recognition
- Invest in You: We support your development through comprehensive training programs, mentoring and opportunities for career advancement
- Thrive as an Individual: We offer a strong work‑life balance with flexible schedules, meaningful perks and a collaborative team environment.